Showing posts with label malwares. Show all posts
Showing posts with label malwares. Show all posts

Friday, December 5, 2008

NEW PASSWORD STEALER TARGETS FIREFOX USERS


Researchers at BitDefender have discovered a new type of malicious software that collects passwords for banking sites but targets only Firefox users.
The malware, which BitDefender dubbed "Trojan.PWS.ChromeInject.A" sits in Firefox's add-ons folder, said Viorel Canja, the head of BitDefender's lab. The malware runs when Firefox is started.
The malware uses JavaScript to identify more than 100 financial and money transfer Web sites, including Barclays, Wachovia, Bank of America, and PayPal along with two dozen or so Italian and Spanish banks. When it recognizes a Web site, it will collect logins and passwords, forwarding that information to a server in Russia.
Firefox has been continually gaining market share against main competitor Internet Explorer since its debut four years ago, which may be one reason why malware authors are looking for new avenues to infect computers, Canja said.
Users could be infected with the Trojan either from a drive-by download, which can infect a PC by exploiting a vulnerability in a browser, or by being duped into downloading it, Canja said.

When it runs on a PC, it registers itself in Firefox's system files as "Greasemonkey," a well-known collection of scripts that add extra functionality to Web pages rendered by Firefox.
BitDefender has updated its products to detect it, and other vendors will likely follow suit quickly, Canja said. Users could avoid it by only downloading signed, verified software, but that's a measure that restricts the usability of a PC, he said.
The malware is not present in Mozilla's repository of add-ons, Canja said. Mozilla had taken steps to ensure that its official site hosting add-ons -- also called extensions -- are free from malware.
In May, Mozilla acknowledged that the Vietnamese language pack for Firefox contained a bit of unwanted code. Although widely reported as a virus, the language actually contained a line of HTML code that would cause users to view unwanted advertisements.
Mozilla now scans new add-ons for malware. However, those scans will only detect known threats, and there was no signature in the security software Mozilla was using at the time that could detect the code.
Mozilla said the code probably ended up in the language pack after the PC of its developer became infected. More than 16,000 people downloaded the language pack, but only about 1,000 people regularly use it.
After the incident, Mozilla said it would scan add-ons in its repository when antivirus signatures were updated.

Stumble Upon Toolbar

Tuesday, October 21, 2008

MALWARE ALERT: 'Experimental' Security Fix Is Malware, Microsoft Says

Scammers are sending out phoney e-mails that claim to include critical Windows security alerts, Microsoft warned Monday.
The fake alerts describe themselves as part of a new "experimental private version of an update for all Microsoft Windows OS users," Microsoft said in a note on the scam, posted Monday.
The e-mails then instruct the victim to download an attachment, which is actually a malicious Trojan Horse program known as Win32/Haxdoor. This software records sensitive information such as passwords and credit card numbers and sends this data back to the attackers who are running the scam.
The malware well-known, however, and is detected by antivirus programs as well as Microsoft's free Microsoft Malicious Software Removal Tool (MSRT).
The warning comes the day before Microsoft is set to deliver 11 genuine security fixes. These updates, due Tuesday at around 10 a.m. Pacific include critical security updates for Windows Active Directory, Internet Explorer, Excel and the Microsoft Host Integration Server.
But they will be delivered via Microsoft's standard automated update tools. Major software vendors such as Microsoft simply do not distribute security patches via email.
"As a matter of company policy, Microsoft will never send you an executable attachment," wrote Microsoft spokesman Christopher Budd in a blog posting on the scam. "If you get an e-mail that claims to be a security notification with an attachment, delete it. It is always a spoof."
Microsoft does, however, send out security notification emails to customers who have asked to be told whenever patches are released or updated. These emails are in plain text and never contain any sort of attachment, Budd said.
Users who have doubts about any security notification email they've received can go to Microsoft's Tech Net security Web site, which contains the same information as its e-mail notifications.


Robert McMillan, IDG News Service

Stumble Upon Toolbar

Tuesday, September 23, 2008

BRAD PITT - REPLACING PARIS HILTON AS BIGGEST MALWARE LURE?



Movie star Brad Pitt has shoved Paris Hilton off the top of a list neither will have coveted being on. A fan entering Pitt's name in a search engine now has a startling one in five chance of finding a malware-hosting site instead, says McAfee.
Pitt is top of the fake website malware league, just ahead of a collection of pop and film stars that reads (in descending order) Beyonce, Justin Timberlake, Heidi Montag, Mariah Carey, Jessica Alba, Lindsay Lohan, Cameron Diaz, George Clooney, and Angelina Jolie.
Hilton no longer even makes the fake web top ten, but can perhaps take some solace from her continued popularity with spammers.
If you're never heard of some of these people then it's a fair bet that you are not the intended target of a technique that has been for some years one of the commonest ways to infect a PC. But still it persists, driven by an apparently insatiable appetite among some Internet users for computer screensavers, wallpaper, ring tones and star pictures, at whatever risk to themselves.
"Cybercriminals employ numerous methods, yet one of the simplest but most effective way is to trick consumers into infecting themselves by capitalizing on Americans' interest in celebrity gossip," commented McAfee's Jeff Green. "Tapping into current events, pop culture or commonly browsed sites is an easy way to achieve this."
Reading the latest statistics, it's hard to avoid the conclusion that malware writers think that the celebrity-obsessed are as recklessly naive as they are star-struck. Most malware-infection techniques have shown some evolution over the last two years, but the fake website ploy just goes on and on.
In fact, a deeper problem is the way users interact with search engines, as was pointed out by McAfee itself only a year ago. McAfee's motives for publicizing the issue aren't entirely neutral - at least one search engine, Yahoo, recently took up using McAfee's SiteAdvisor tool to filter the websites it returns in search boxes.
And for those users who only visit legitimate websites they know about, there is also bad news. The biggest hack trend of the last year has been compromising perfectly legitimate websites to serve malware - witness this week's large attack on the website of BusinessWeek magazine. For Internet users there is no easy escape, only the awareness of the growing number of pitfalls.

Techworld.com
Sep 21, 2008 5:05 am

Stumble Upon Toolbar

Search Engine Spider Simulator

Enter URL to Spider